PT-2026-57298 · Vmware+1 · Rabbitmq+1

CVE-2026-57213

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

5.7

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.14 RabbitMQ versions prior to 4.0.19 RabbitMQ versions prior to 4.1.10 RabbitMQ versions prior to 4.2.5
Description The rabbitmq federation management plugin fails to perform HTML escaping when rendering the consumer tag field on the Federation Status page. This allows a user with permissions to configure a federation upstream or policy to execute arbitrary JavaScript in the browser of any user viewing that page.
Recommendations Update to version 3.13.14 or later. Update to version 4.0.19 or later. Update to version 4.1.10 or later. Update to version 4.2.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92343
CVE-2026-57213
GHSA-QXRP-7CMP-P77H
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq
Rabbitmq Federation Management